Hiring.Camp

Cybersecurity Analyst Intern

Roche

·

Today

Location
Sant Cugat del Valles, Spain
Type
Internship
Department
IT
Seniority
Internship
Source
Workday

Description

At Roche you can show up as yourself, embraced for the unique qualities you bring. Our culture encourages personal expression, open dialogue, and genuine connections,  where you are valued, accepted and respected for who you are, allowing you to thrive both personally and professionally. This is how we aim to prevent, stop and cure diseases and ensure everyone has access to healthcare today and for generations to come. Join Roche, where every voice matters.

The Position

Threat & Vulnerability Analyst (Product Security)


The Opportunity

At Roche, we believe that secure products build trust and save lives. As a Threat & Vulnerability Analyst, you will play a pivotal role in safeguarding our healthcare products, software platforms, and medical technology ecosystem.

You will be responsible for identifying, evaluating, and reporting security vulnerabilities across product lines while leveraging cutting-edge automation and AI-driven methodologies. Working at the intersection of cybersecurity, engineering, and product innovation, you will serve as a trusted security partner to product development teams: helping them understand security risks, prioritize remediations, and continuously strengthen our security posture.

Key Responsibilities

  • Vulnerability Assessment & Analysis: Perform end-to-end security assessments on product components and software stacks, identifying potential security flaws, exposure points, and software risks.
  • Automation & AI Integration: Contribute actively to the automation of Software Bill of Materials (SBOM) vulnerability management workflows and help pioneer AI-augmented vulnerability assessment frameworks to scale security operations.
  • Cross-Stakeholder Reporting: Translate complex technical vulnerabilities into clear, actionable risk reports for engineering, product management, and leadership teams.
  • Product Team Enablement & Remediation Support: Partner directly with product teams to help them comprehend vulnerability root causes and potential impact, collaborate on pragmatic and effective remediation strategies, and assist in prioritizing fixes within development roadmaps.
  • Continuous Improvement: Track emerging threat vectors, zero-days, and security industry standards (such as CVSS, NIST, OWASP) to continuously refine assessment criteria and automated tooling.

Who You Are

You are a proactive, analytical cybersecurity professional who thrives on solving complex technical challenges and communicating security concepts to both technical and non-technical audiences.

Qualifications & Skills:

  • Experience: Proven experience in threat and vulnerability management, product security, application security, or software security analysis.
  • Technical Knowledge: Strong understanding of vulnerability scoring systems (e.g., CVSS), Software Bill of Materials (SBOM) management, software composition analysis (SCA), and common vulnerability frameworks (CVE/CWE).
  • Automation & Scripting: Demonstrated ability or strong interest in automating security workflows (e.g., Python, Bash, CI/CD integrations) and applying emerging AI/ML technologies to security assessments.
  • Remediation Strategy: Ability to guide engineering teams through root-cause analysis and realistic fix prioritization without compromising delivery velocity.
  • Communication & Influence: Excellent written and verbal communication skills, with a track record of building positive, consultative relationships with software and product teams.

 

 

Who we are

A healthier future drives us to innovate. Together, more than 100’000 employees across the globe are dedicated to advance science, ensuring everyone has access to healthcare today and for generations to come. Our efforts result in more than 26 million people treated with our medicines and over 30 billion tests conducted using our Diagnostics products. We empower each other to explore new possibilities, foster creativity, and keep our ambitions high, so we can deliver life-changing healthcare solutions that make a global impact.


Let’s build a healthier future, together.

Roche is an Equal Opportunity Employer.

Skills

PythonCI/CDCybersecurity

Similar Jobs

2

[Keppel Internship Programme 2027] Intern, Cybersecurity Analyst (Jan - May 2027)

Keppel · SGP Changi Business Park, Singapore

6 days ago

Cybersecurity Analyst - Master-Level Internship

Vosyn · Etobicoke, ON, CA · Remote

1+ year ago